Live data from Hacker News

U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

krebsonsecurity.com

201–210 of 350 posts

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#201
post #42

Earlier quoted context omitted.

Am I missing something? Why is everyone so sure that it is Russia? Are they the only ones with access to computers beside US?

Because Russia has somewhat of an oil monopoly in Europe and the US doesn't like that. We've been being fed Russia war propaganda for at least a decade. If it even feels like a "Russia kind of thing" to the general public that is just the result of intentional conditioning by warmongers. It could have been literally any major world power, including our allies. No evidence has been presented whatsoever as to who the c…

Hell, it could be a different part of the USA government, like those "sonic embassy attacks" were.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#202

A couple of quick notes: 1) The OPM hack and now this all illustrate - if govt gives itself the big backdoors into everything, it's likely they will give it to russia, criminals, ex-boyfriends stalking ex-girlfriends etc. 2) My own impression of govt IT is largely security theatre in the area I was involved. In particular such massive complexity that agency staff think going around the rules is normal, because it's t…

> With google I've had one password for 20 years (my google account) which allows a hardware key for 2FA or google authenticator with what I imagine is sensible monitoring, new device authentication etc (I find this pretty secure).

I too hope this is not just security theater as well.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#203

Earlier quoted context omitted.

Maybe they were just bribed?

An employee, possibly. The whole company, unlikely. And either way, even if someone was bribed to introduce the attack there's zero reason to allow the hacked software to be downloaded now. I work at a large and highly regulated (HIPAA) company and we have the equivalent of Electric Dylan/Pete Seeger with the axe: if someone at the VP+ level declares a major incident, our infosec team has a script that will lock down…

>if someone at the VP+ level declares a major incident [...]

I read this as, "we have a policy that under no circumstances will someone at a VP+ level declare a major incident."

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#204

Wow the hackers had free rein over basically any company that they wanted. SolarWinds says it has over 300,000 customers including: -more than 425 of the U.S. Fortune 500 -all ten of the top ten US telecommunications companies -all five branches of the U.S. military -all five of the top five U.S. accounting firms -the Pentagon -the State Department -the National Security Agency -the Department of Justice -The White H…

As a user of Ignite, we're struggling to find an alternative that matches its feature set. Great business opportunity here.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#205

A couple of quick notes: 1) The OPM hack and now this all illustrate - if govt gives itself the big backdoors into everything, it's likely they will give it to russia, criminals, ex-boyfriends stalking ex-girlfriends etc. 2) My own impression of govt IT is largely security theatre in the area I was involved. In particular such massive complexity that agency staff think going around the rules is normal, because it's t…

You should check out the new CMMC requirements -- basically a new set of basic cyber security requirements for all DoD suppliers, starting next year.

It's heavily based on the NIST guidelines, so strong on 2FA, and discourages arbitrary password rotation.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#206

SolarWinds hasn't bothered to revoke their certs or remove the package https://twitter.com/KyleHanslovan/status/1338360093767823362 Back in 2019 apparently their FTP server credentials were exposed on GitHub, allowing automated updates being pushed https://twitter.com/vinodsparrow/status/1338431183588188160/... Edit: If updates failed due to signature not matching, SolarWinds recommended downloading the package and i…

Clearly whoever is the CIO/CISO could care less? I find it hilarious that people get these positions without seemingly a care in the world. Or maybe they do care and the CEO didn't? Hardly anyone ever gets fired in these circumstances.

Surely he COULDN'T care less?

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#207

This also came out today: https://mattermost.com/blog/coordinated-disclosure-go-xml-vu... It seems pretty likely that SolarWinds' SAML authentication was bypassed or escalated by this issue with Go's encoding/xml, and then used that to generate and distribute the trojaned SolarWind's updates.

Doubt it - that bug has been known by Go/Mattermost since August.

How would SolarWinds know about it if it wasn't publicly disclosed until today?

Also, I realize the SAML -> SolarWinds connection is a bit of speculation on my part, but SAML is mentioned in Microsoft's advisory: https://msrc-blog.microsoft.com/2020/12/13/customer-guidance...

It sounds like a privilege escalation using the Go/SAML issue.

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#208

Earlier quoted context omitted.

> SolarWinds hasn't bothered to revoke their certs or remove the package Amazing. While I'm sure the attackers have already shut up shop and the threat no longer exists, this feels insanely tone-deaf from SolarWinds.

Maybe they were just bribed?

[deleted]

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#209

Earlier quoted context omitted.

Yeah, I know it's not actually recommended anymore, but the policy makers don't care. They're doing CYA policy. They do whatever seems to be the strongest possible thing, users and reality be damned. I was in a team whose security group eliminated the use of DVD drives for reading (not writing) data except for a few permitted individuals. Creating a massive chokepoint in every process where data had to come from off-…

> They do whatever seems to be the strongest possible thing It's not that, it's inertia and poor incentive structures. In a large organization, if a policy was set in place by someone else, then, even when you know it's a sub-par policy, it's still in your interest to leave it alone. Doing so gives you a way to deflect blame in the event of a breach related to that decision. You can just blame the policy itself. If,…

It's certainly possible that in some cases that's true, but there are a lot of government check-box security people who genuinely believe complex passwords rotated frequently are a good security control. There's also a general heuristic with many people in security that the more convenient something is, the less secure it is. Therefore smart card auth must be worse!

Re: U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

#210
post #41

A couple of quick notes: 1) The OPM hack and now this all illustrate - if govt gives itself the big backdoors into everything, it's likely they will give it to russia, criminals, ex-boyfriends stalking ex-girlfriends etc. 2) My own impression of govt IT is largely security theatre in the area I was involved. In particular such massive complexity that agency staff think going around the rules is normal, because it's t…

For what it's worth NIST password guidance SP800-63b no longer advises the arbitrary expiration, so hopefully this is something that will change. >“Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically). However, verifiers SHALL force a change if there is evidence of compromise of the authenticator.”

Has this shown up everywhere. Govt agencies still had it in contract docs. That might mean fedramp or PCI or some other standard still mandates it.

Enforces minimum password complexity of case sensitivity, number of characters, mix of upper-case letters, lower-case letters, numbers, and special characters, including minimum requirements for each type; Enforces at least 5 changed characters when new passwords are created: Stores and transmits only cryptographically-protected passwords; Enforces password minimum and maximum lifetime restrictions of 60 days; Prohibits password reuse for 10 generations ...

Post reply on HN